作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (18): 184-185. doi: 10.3969/j.issn.1000-3428.2008.18.065

• 安全技术 • 上一篇    下一篇

一种无监督网络入侵检测算法

郑洪英1,倪 霖2   

  1. (1. 重庆大学计算机科学与工程学院,重庆 400030;2. 重庆大学机械工程学院,重庆 400030)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-09-20 发布日期:2008-09-20

Unsupervised Network Intrusion Detection Algorithm

ZHENG Hong-ying1, NI Lin2   

  1. (1. Department of Computer Science and Engineering, Chongqing University, Chongqing 400030;2. Department of Mechanic Engineering, Chongqing University, Chongqing 400030)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-09-20 Published:2008-09-20

摘要: 多数入侵检测方法对训练数据集存在依赖,带标识的训练数据集在现实环境中难以被获取,无法保证所得标签数据能覆盖所有可能出现的攻击。该文提出基于无人监督聚类和混沌模拟退火算法的网络入侵检测方法,混沌模拟退火算法实现对聚类结果的优化,求得聚类的全局最优解,提高了数据分类的准确性和检测效率。在KDD CUP 1999上的仿真实验结果表明,该算法可实现预期效果。

关键词: 网络入侵检测, 聚类, 混沌, 模拟退火算法

Abstract: Most intrusion detection methods are dependent on training data sets. Labeled training data sets are difficult to be obtain and one can never be sure that a set of available labeled data covers all possible attacks. This paper proposes a network intrusion detection method based on unsupervised clustering and chaos simulated annealing algorithm. Chaos simulated annealing algorithm is used to optimize clustering results to get the global optimal solution, upgrade the accuracy of classification, and improve the quality of intrusion detection. Experiments are completed on KDD Cup 1999 and expectant results are achieved.

Key words: network intrusion detection, clustering, chaos, simulated annealing algorithm

中图分类号: